CVE-2026-15420

Nexter Blocks <= 5.0.0 - Authenticated (Subscriber+) Path Traversal to Arbitrary CSS/JS File Deletion via 'plus_name' Parameter

The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 5.0.0 via the 'plus_name' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary JS/CSS files on the server, which can lead to denial of service or destruction of critical plugin and theme assets.


We have discovered 516 live websites that are affected by CVE-2026-15420.

Run a Free Instant Scan




Affected Software

Product  The Plus Addons For Block Editor
Category Wordpress Plugins
Vulnerable Domains516 live websites (100% of The Plus Addons For Block Editor install base)
Vulnerable Versions
  • from 0 through 5
Vulnerable Versions Count47 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')



Details

  • Published - Jul 24, 2026
  • Updated - Jul 24, 2026

Credits

  • Wordfence PRISM (finder)

Website Distribution by Country

Number of websites using CVE-2026-15420
United States198 websites



Germany57 websites
GB24 websites
France24 websites
Australia19 websites
Canada17 websites
India12 websites
Netherlands12 websites
Slovenia11 websites
South Africa10 websites

Website Distribution by TLD

Number of websites using CVE-2026-15420
.com224 websites
.org62 websites
.de37 websites
.com.au16 websites
.nl14 websites
.ca10 websites
.fr10 websites
.it7 websites
.net7 websites
.co.uk7 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-15420

Top websites that are affected by CVE-2026-15420. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.com United States**,***
****.org United States**,***
*******.com France***,***
*********.com GB***,***
********.com United States***,***
***************.org United States***,***
****.edu United States***,***
*************.org United States***,***
******.**************.org United States***,***
**********.org United States***,***
See full domain list

FAQ

CVE-2026-15420 is Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in The Plus Addons For Block Editor
A total of 516 websites have been identified as vulnerable to CVE-2026-15420, based on global website indexing conducted by WebTechSurvey.
The The Plus Addons For Block Editor is affected by the CVE-2026-15420 vulnerability.
The Plus Addons For Block Editor versions up to and including 5 are vulnerable to CVE-2026-15420.

References